3 ms·
that's true but especially code hosting sites, should be a bit more concerned. Using a WAF and white listing parameters, may be a good start too. Just another
by mcorrientes 16y ago
that's true but especially code hosting sites, should be a bit more concerned.
Using a WAF and white listing parameters, may be a good start too.
Just another reason why I keep the code internal.
- Xk 16y ago> especially code hosting sites, should be a bit more concerned. Not really. There are many examples of sites which should be more concerned. Anything with your credit card information, say. > Using a WAF and white listing parameters Yeah, that's a good start. But you need to make sure everything goes through the white list, and that's the hard part. > Just another reason why I keep the code internal. What does this have to do with security?
- d1b 16y agoI think in the github and launchpad case the security that a WAF normally offers would have been broken because the data to trigger the vector did not come through http nor https. I suggest you have a play around with github wiki's they already have 'html sanitization' built in.